Welcome,
Guest
.
Please
login
or
register
.
Did you miss your
activation email
?
News:
Did you know that
Elxis 5.x
uses HTML5, CSS3 and pure javascript without external libraries such as jQuery?
Home
Help
Login
Register
Elxis CMS Forum
»
Support
»
Technical support
»
Suggested improvement to Defender and Floodblocker
« previous
next »
Print
Pages: [
1
]
Author
Topic: Suggested improvement to Defender and Floodblocker (Read 7797 times)
empusa
Newbie
Posts: 8
Suggested improvement to Defender and Floodblocker
«
on:
June 30, 2008, 18:34:16 »
Having managed to shut myself out of my own sites several times via both Defender and Floodblocker, I thought I would suggest an improvement.
I would like to be able to add/amend pages without triggering Defender or Floodblocker. I also don't like the idea of switching them off in order to do any updates to the site.
I currently block access to my administrator section to all but three IP addresses. Could these allowed IP addresses be included in /includes/Core/security.php to prevent the allowed IP addresses from triggering Defender and Floodblocker.
Also, allowed IP addresses should then never be added to the blocked list.
That way, Defender can be set to block IP addresses without ever running the risk of locking out the site's administrator.
Logged
Ivan Trebješanin
Elxis Team
Hero Member
Posts: 1663
Re: Suggested improvement to Defender and Floodblocker
«
Reply #1 on:
June 30, 2008, 19:04:00 »
Hmmm, are you saying that defender blocked your IP in spite of being on allowed IP list?
Logged
I've got a snap in my finger...
Got rhythm in my walk...
empusa
Newbie
Posts: 8
Re: Suggested improvement to Defender and Floodblocker
«
Reply #2 on:
June 30, 2008, 19:27:19 »
Certainly did.
I just got Defender to trigger again to make sure. It also logged me out.
Allowed IP addresses (3)
Only the IP addresses bellow have access to Administration:
• xx.69.91.190 • xx.233.54.56 • xx.32.57.6
View Logs (1)
# IP Date Filters
1 xx.69.91.190 [GEO 1] [GEO 2] Monday, 30 June 2008 16:57:48 mosConfig_
«
Last Edit: June 30, 2008, 19:31:22 by empusa
»
Logged
Ivan Trebješanin
Elxis Team
Hero Member
Posts: 1663
Re: Suggested improvement to Defender and Floodblocker
«
Reply #3 on:
June 30, 2008, 19:59:41 »
Ooops... thank you for this info.
Logged
I've got a snap in my finger...
Got rhythm in my walk...
datahell
Elxis Team
Hero Member
Posts: 10356
Re: Suggested improvement to Defender and Floodblocker
«
Reply #4 on:
June 30, 2008, 21:03:37 »
The allowed IP feature has an other usage that the blocking one. By adding your IP to the allowed IP addresses does not prevent Defender from blocking you out of the site.
The allowed IP feature is used to limit the access to the administration area to only specific IP addresses
and should be used only if you have a static Internet connection. Defender and FloodBlocker can not accept exceptions even for the super administrator as they are security tools and there must not be any way to be able to bypass them by spoofing a server request. If Defender/FloodBlocker ban/block you just clear their log files via FTP or edit their config.php file via FTP and disable them temporary until you unban your self.
I believe that both tools are working great and there is no need to change the way they work.
Tip:
You can have almost the same result as the allowed IP feature if you use an other Elxis security option the
cloaking of the administration login page
. It is a fast and easy option that prevents even the login attempts to the administration console.
«
Last Edit: June 30, 2008, 21:11:52 by datahell
»
Logged
Elxis Team
|
Is Open Source
|
IOS Rentals | IOS AERO
rentasite
Elxis Community
Hero Member
Posts: 3282
Web Services
Re: Suggested improvement to Defender and Floodblocker
«
Reply #5 on:
June 30, 2008, 21:11:59 »
Quote from: datahell on June 30, 2008, 21:03:37
I believe that both tools are working great and there is no need to change the way they work.
Exactly !!!
Logged
Rent a Site
|
Lelevose
datahell
Elxis Team
Hero Member
Posts: 10356
Re: Suggested improvement to Defender and Floodblocker
«
Reply #6 on:
June 30, 2008, 21:33:19 »
An other thing I wish to add for those having SEO PRO enabled is that the htaccess file used by SEO PRO has build-in some security settings for some Elxis variables such as the mosConfig_... configuration variables. If you use SEO PRO we will see that you have very rare messages from the Elxis Defender and this is because apache blocks that requests before they even proceed to the Elxis Defender. If you disable SEO PRO, Elxis Defender will have much more work to do. I often say that SEO PRO does much more things than a simple URL rewrite and this is one of the additional things it does (an other important task it does is that it fixes automatically some menu related issues). SEO PRO in Elxis 2008.1 goes a step further as it also manages Elxis language.
«
Last Edit: June 30, 2008, 21:35:59 by datahell
»
Logged
Elxis Team
|
Is Open Source
|
IOS Rentals | IOS AERO
Print
Pages: [
1
]
« previous
next »
Elxis CMS Forum
»
Support
»
Technical support
»
Suggested improvement to Defender and Floodblocker